Privacy Policy
Last updated: June 11, 2026
This Privacy Policy governs the data privacy practices of We Ship CRMs LLC, a Delaware registered limited liability company doing business as ShipCRM (collectively, "the Company," "we," "us," or "our").
We respect your privacy and are committed to protecting the personal data we process about you. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data when you visit our website, use our Software-as-a-Service (SaaS) CRM platform, or otherwise interact with us.
Scope of This Policy: Our Roles as Controller and Processor
We handle personal data in two different roles, and this Policy applies differently to each:
As a Controller. For personal data we collect about website visitors, prospects, and our business customers and their authorized users (for example, account-registration details, billing information, support communications, and website-usage data), We Ship CRMs LLC determines the purposes and means of processing and acts as the "Controller." This Policy governs that data.
As a Processor. For the contacts, leads, records, and other data that a customer uploads into its ShipCRM workspace ("CRM Data," the "Customer Data" defined in our Terms of Service), we act as a "Processor" that processes the data only on the customer's behalf and under its instructions, pursuant to our Data Processing Addendum (DPA). The customer is the Controller of CRM Data, and the customer's own privacy policy — not this Policy — governs how that data may be used. If you are an individual whose data appears in a customer's workspace and you wish to exercise rights, please contact that customer (the Controller); we will assist them as required by law.
1. Corporate Identity and Contact Details
Pursuant to applicable data protection laws, We Ship CRMs LLC is the "Data Controller" of the personal data described in the "Scope of This Policy" section above (data about visitors, account holders, prospects, and billing). For CRM Data that customers upload to their workspace, we act as a "Processor" under our Data Processing Addendum, and this Policy does not govern that data.
- Legal Entity Name: We Ship CRMs LLC (dba ShipCRM)
- Registered Office Address: 8 The Green Suite B, Dover, DE 19901
- Company Management: Robert Malko, Manager
- Contact Email: support@shipcrm.ai
2. Categories of Information We Collect
We collect information that identifies, relates to, describes, or is reasonably capable of being associated with you ("Personal Data"). The types of data we collect depend on how you interact with our platform.
| Category of Personal Data | Specific Examples | Source of Collection |
|---|---|---|
| Identifiers | Full name, business email address, phone number, mailing address, unique personal identifier, IP address, and account login credentials. | Directly from you during account registration or webform submissions. |
| Commercial Information | Billing details, transaction histories, subscription plans, and records of services purchased or considered. | Directly from you and via our secure third-party payment processors. |
| Internet or Network Activity | Browser type, operating system, device information, browsing history, clickstream data, search history, and interactions with our website or application. | Automatically collected via cookies and web beacons. |
| User-Generated CRM Data | Contact lists, customer interactions, lead records, and notes uploaded to your ShipCRM workspace. | Provided directly by you (or your organization) as part of using our CRM services. |
Note on Sensitive Data: We do not intentionally collect or process "Sensitive Data" (e.g., Social Security numbers, racial or ethnic origin, precise geolocation, health data, or biometric information). Please do not upload sensitive personal data into your CRM workspace.
Processor Role for CRM Data: Where the table above refers to User-Generated CRM Data, we process that data as a Processor on behalf of our business customers under our Data Processing Addendum; the customer is the Controller of that data. See "Scope of This Policy" above.
3. How and Why We Use Your Information
We process your Personal Data under valid legal bases, including to fulfill our contractual obligations to you, to pursue our legitimate business interests, and to comply with legal mandates.
Specifically, we use your data to:
- Provide and Maintain the Services: Provision your CRM account, host your data, and ensure operational functionality.
- Process Payments: Securely handle transaction processing and subscription renewals through our PCI-compliant payment gateways.
- Customer Support: Diagnose technical issues, resolve customer tickets, and respond to inquiries.
- Product Optimization: Analyze usage patterns to develop updates, fix bugs, and roll out new product features.
- Marketing and Communications: Send you system notifications, security alerts, product updates, and promotional materials (where permitted by law).
- Security and Compliance: Protect against fraud, malicious activity, and unauthorized system access, as well as comply with statutory requirements.
Legal Bases for Processing (GDPR/UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases: (a) performance of a contract, to provide the Services and process payments; (b) our legitimate interests, to secure, support, and improve the Services and for limited business communications, balanced against your rights; (c) consent, for non-essential cookies and certain marketing, which you may withdraw at any time; and (d) compliance with legal obligations.
Automated Processing and AI Profiling
Our Services include artificial-intelligence features that analyze, score, summarize, and prioritize data (including profiling of leads and contacts) to support sales and marketing decisions. These features are decision-support tools and are not used to make decisions producing legal or similarly significant effects about you based solely on automated processing. Where required by law, you may request human review of, or object to, such processing, and (for CRM Data) we will direct such requests to the relevant customer as Controller. Consistent with our Terms of Service, we do not use Customer Data to train shared or general-purpose AI models.
4. How We Share and Disclose Your Information
We do not sell your personal data to third parties for monetary gain. However, we may disclose your information to trusted third-party service providers ("Processors") to help us operate our platform:
- Cloud Hosting and Database: Fly.io, Inc. (United States), to host the platform and store your data.
- Payments: Polar (polar.sh), our merchant of record, to process subscription billing and payments.
- AI Features: Anthropic, PBC (Claude), to power AI suggestions, drafting, scoring, and summaries. Anthropic does not train its models on data submitted through its commercial API.
- Email Delivery: Mailjet (a Sinch company), to send transactional and system emails.
- Translation: Microsoft Azure AI Translator, to translate text within the Services where used.
- Authentication and Google Workspace: Google LLC, for Google sign-in and, where you connect it, Gmail and Google Calendar integration.
- Legal Obligations: We may disclose your data if required by law, subpoena, or government order, or if we believe disclosure is necessary to protect our legal rights or prevent fraud.
- Corporate Transfers: In the event of a merger, acquisition, consolidation, or asset sale, your personal data may be transferred to the acquiring entity, subject to this Privacy Policy.
No Sale or Sharing of Personal Information: We do not sell your personal data, and in the preceding twelve (12) months we have not sold personal information or shared it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not use or disclose Sensitive Personal Information for purposes that would trigger a right to limit its use under the CCPA/CPRA.
5. Cookies and Tracking Technologies
We and our service providers use cookies and similar technologies (web beacons, pixels, local storage) to operate our website and Services and remember your preferences.
Categories: (a) Strictly necessary cookies, required for the site and platform to function and for security and authentication; (b) Functional cookies, which remember your settings; and (c) Analytics/performance cookies (not currently used; if introduced, set only with your consent in the EEA and UK).
Your choices: You can manage non-essential cookies through our cookie banner or settings where offered, and through your browser controls. In the EEA and UK, we set non-essential cookies only with your consent. We honor Global Privacy Control (GPC) signals as an opt-out of targeted advertising/sharing where applicable. For details, see our separate Cookie Policy.
6. Data Retention and Security
Data Retention
We retain your Personal Data only as long as your account remains active or as necessary to fulfill the purposes outlined in this policy. If you terminate your account, we will retain your data for a 30-day export grace period and then delete or anonymize it, unless extended retention is required to fulfill legal, accounting, tax, or regulatory obligations.
Data Security
We implement robust, industry-standard technical, organizational, and physical security measures designed to safeguard your Personal Data against unauthorized access, destruction, loss, or alteration. These measures include:
- Encryption of data in transit (using HTTPS/TLS) and at rest.
- Role-based access controls for employees with access to system databases.
- Regular security scanning and software patch management.
7. State-Specific and Global Privacy Rights
Depending on your geographic location, you may possess specific legal rights regarding your Personal Data under frameworks such as the Delaware Personal Data Privacy Act (DPDPA), the California Consumer Privacy Act (CCPA/CPRA), and the General Data Protection Regulation (GDPR).
Your Consumer Rights
- Right to Access / Know: Confirm if we process your data and obtain a copy of the specific data collected.
- Right to Disclosure: Obtain a list of the specific categories of third parties to whom your data has been disclosed.
- Right to Rectification: Request corrections to inaccurate or outdated Personal Data.
- Right to Deletion: Request the erasure of your Personal Data, subject to standard statutory exemptions.
- Right to Portability: Receive your data in a portable, structured, and readily usable format.
- Right to Opt-Out: Opt-out of targeted advertising, profiling, or the sale of your data.
- Right to Non-Discrimination: Exercise your privacy rights without facing price increases or service degradation.
Delaware Personal Data Privacy Act (DPDPA) Notice
As a Delaware registered entity, we strictly adhere to the DPDPA.
- Universal Opt-Out Mechanisms (UOOMs): In compliance with Delaware law, our systems are configured to automatically recognize and honor global privacy controls and universal opt-out signals (such as Global Privacy Control / GPC) sent via your web browser.
- Authorized Agents: You may designate an authorized agent to make rights requests on your behalf.
How to Exercise Your Rights
To submit a request to access, correct, delete, or opt-out of processing, please email us directly at support@shipcrm.ai with the subject line "Privacy Rights Request." We will verify your identity before processing the request and respond within 45 days of receipt.
Response Timeframes: We respond within the timeframe required by applicable law — generally within 45 days under U.S. state privacy laws (extendable as permitted), and within one month under the GDPR (extendable to three months for complex requests). Requests should be sent to support@shipcrm.ai.
8. International Data Transfers
We Ship CRMs LLC operates primarily out of the United States. If you access our services from the European Economic Area (EEA), the United Kingdom, or Canada, your Personal Data will be transferred to and processed within the United States. We utilize approved standard contractual clauses (SCCs) and appropriate legal mechanisms to guarantee that your data receives an equivalent level of protection to that mandated in your home jurisdiction.
EU/UK Representative: If we do not have an establishment in the EEA or UK and Article 27 GDPR/UK GDPR applies, we will appoint and identify here our EU and UK representatives and their contact details.
9. Children's Privacy
Our services are strictly business-to-business (B2B) CRM tools and are not intended for or directed toward individuals under the age of 18. We do not knowingly collect, store, or process Personal Data from children. If we discover we have inadvertently collected data from an individual under 18, we will purge it from our systems immediately.
10. Appeals and Regulatory Complaints
If we deny your privacy request, you have the right to appeal our decision by responding to our denial email or messaging support@shipcrm.ai within 30 days of our response. We will respond to your appeal within 45 days.
If your appeal is denied or unresolved, you have the legal right to file a formal complaint with the appropriate regulatory authority:
- Delaware Residents: You may submit a data privacy complaint to the Delaware Department of Justice by emailing privacy@delaware.gov.
- European / UK Residents: You may lodge a complaint with your local Data Protection Authority (DPA) or Information Commissioner's Office (ICO).
11. Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect shifts in our operational practices or shifting regulatory landscapes. We will notify you of material changes by posting the updated policy conspicuously on our website, updating the "Effective Date" at the top, or emailing account holders directly. Continued use of our platform after updates take effect constitutes acknowledgment of the revised policy.